HIGH

CVE-2023-21674

Microsoft Windows 10 1507 2023-01-10 CVSS v3.1
CVSS
8.8
KEV

Description

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

Summary dbcve.org

This is a Windows Elevation of Privilege vulnerability in the Advanced Local Procedure Call (ALPC) mechanism. ALPC is an inter-process communication facility used extensively by Windows components. An attacker who successfully exploits this vulnerability could gain higher privileges on the affected system, potentially executing arbitrary code in SYSTEM or kernel context.

Mitigation

Apply the Microsoft security update for CVE-2023-21674 to all affected Windows systems. Validate that ALPC-related system components are properly patched and verify the patch deployment across the environment.

Patch Commit

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

41.81%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE